Human approval for AI agents: what to approve, what to let run

AI agents that pay, post or delete need a human yes. Which actions need approval, how standing permissions work, and why you need a kill switch.

The fastest way to lose trust in AI agents is one bad action: an email to the wrong list, a deleted folder, an ad budget raised by mistake. The fix isn't to stop using agents. It's to put a person in the loop at the right moments, and nowhere else.

The rule of thumb

Let the AI do anything that is easy to undo or only reads. Ask a person before anything that is hard to undo or reaches other people.

Usually fine without askingAsk first
Reading dashboards and reportsPaying or buying anything
Drafting emails, posts and repliesSending messages, emails or posts to people
Updating your own notes and trackersDeleting files, posts or contacts
Downloading reportsChanging passwords, settings or permissions
Searching the webUsing your bank or payment logins

AgentDaftar ships with every item in the right column set to ask. You can relax them per office once you trust a workflow.

Make approval fast

An approval nobody sees is just a stuck task. Approvals work when they:

  • Reach your phone. AgentDaftar sends them to Telegram with buttons: Yes, once, Always for this task, No.
  • Say exactly what will happen. The kind of action, the task it belongs to, the recipients and the amount.
  • Expire. Unanswered requests expire after 24 hours, so nothing old gets approved by accident.

Standing permissions, done safely

Approving the same daily report every morning gets old. A standing permission says "yes to this, from now on". The danger is a permission that's too broad: a misled AI could stretch "send the daily report" into "send anything to anyone".

So keep standing permissions narrow. In AgentDaftar, tapping Always for this task creates one that covers:

  • the same kind of action,
  • for the same task,
  • to the same recipients,
  • at most so many times a day and up to an amount,
  • until an end date (90 days by default).

Anything outside those limits is asked again.

Every team needs a kill switch

When something looks wrong, you don't want to find the right setting. You want one button. AgentDaftar's kill switch stops every AI at once: their actions are refused and running commands end. It's in the panel, and on Telegram as /stop (or /stop pc1 for one employee). /resume starts them again.

Keep a record

Approvals are half the story; the other half is being able to check what happened. Keep an activity log per agent, screen recordings of AI sessions, and a history of who changed which rule. When something goes wrong, you'll know exactly what and why.

Start strict, then relax

Begin with everything risky on ask. Watch a workflow for a week. When you've approved the same thing ten times without changes, give it a narrow standing permission. That's how teams go from nervous to confident with AI agents without a single bad surprise.

See how it works in AgentDaftar approvals, or read what an AI employee is.